Layer: kernel

Policy for kernel threads, proc filesystem, and unlabeled processes and objects.


Module:Description:
corecommands

Core policy for shells, and generic programs in /bin, /sbin, /usr/bin, and /usr/sbin.

corenetwork

Policy controlling access to network objects

devices

Device nodes and interfaces for many basic system devices.

domain

Core policy for domains.

files

Basic filesystem types and interfaces.

filesystem

Policy for filesystems.

kernel

Policy for kernel threads, proc filesystem, and unlabeled processes and objects.

mcs

Multicategory security policy

mls

Multilevel security policy

selinux

Policy for kernel security interface, in particular, selinuxfs.

storage

Policy controlling access to storage devices

terminal

Policy for terminals.

ubac

User-based access control policy

unlabelednet

Policy for allowing confined domains to use unlabeled_t packets



Layer: roles

Policy modules for user roles.


Module:Description:
auditadm

Audit administrator role

logadm

Log administrator role

secadm

Security administrator role

staff

Administrator's unprivileged user

sysadm

General system administration role

sysadm_secadm

No Interfaces

unconfineduser

Unconfined user role

unprivuser

Generic unprivileged user



Layer: admin

Policy modules for administrative functions, such as package management.


Module:Description:
bootloader

Policy for the kernel modules, kernel image, and bootloader.

consoletype

Determine of the console connected to the controlling terminal.

dmesg

Policy for dmesg.

netutils

Network analysis utilities

su

Run shells with substitute user and group

sudo

Execute a command with a substitute user

usermanage

Policy for managing user accounts.



Layer: apps

Policy modules for applications


Module:Description:
seunshare

Filesystem namespacing/polyinstantiation application.



Layer: system

Policy modules for system functions from init to multi-user login.


Module:Description:
application

Policy for user executable applications.

authlogin

Common policy for authentication and user login.

clock

Policy for reading and setting the hardware clock.

fstools

Tools for filesystem management, such as mkfs and fsck.

getty

Policy for getty.

hostname

Policy for changing the system host name.

hotplug

Policy for hotplug system, for supporting the connection and disconnection of devices at runtime.

init

System initialization programs (init and init scripts).

ipsec

TCP/IP encryption

iptables

Policy for iptables.

kdbus

Policy for kdbusfs.

libraries

Policy for system libraries.

locallogin

Policy for local logins.

logging

Policy for the kernel message logger and system logging daemon.

lvm

Policy for logical volume management programs.

miscfiles

Miscelaneous files.

modutils

Policy for kernel module utilities

mount

Policy for mount.

netlabel

NetLabel/CIPSO labeled networking management

selinuxutil

Policy for SELinux policy and userland applications.

setrans

SELinux MLS/MCS label translation service.

sysnetwork

Policy for network configuration: ifconfig and dhcp client.

systemd

SELinux policy for systemd components

udev

Policy for udev.

unconfined

The unconfined domain.

userdomain

Policy for user domains



Layer: services

Policy modules for system services, like cron, and network services, like sshd.


Module:Description:
postgresql

PostgreSQL relational database

ssh

Secure shell client and server policy.

xserver

X Windows Server



Layer: contrib

Contributed Reference Policy modules.


Module:Description:
abrt

ABRT - automated bug-reporting tool

accountsd

AccountsService and daemon for manipulating user account information via D-Bus.

acct

Berkeley process accounting.

ada

GNAT Ada95 compiler.

afs

Andrew Filesystem server.

aiccu

Automatic IPv6 Connectivity Client Utility.

aide

Aide filesystem integrity checker.

aisexec

Aisexec Cluster Engine.

ajaxterm

policy for ajaxterm

alsa

Advanced Linux Sound Architecture utilities.

amanda

Advanced Maryland Automatic Network Disk Archiver.

amavis

High-performance interface between an email server and content checkers.

amtu

Abstract Machine Test Utility.

anaconda

Anaconda installer.

antivirus

SELinux policy for antivirus programs - amavis, clamd, freshclam and clamscan

apache

Apache web server

apcupsd

APC UPS monitoring daemon.

apm

Advanced power management.

apt

Advanced package tool.

arpwatch

Ethernet activity monitor.

asterisk

Asterisk IP telephony server.

authbind

Tool for non-root processes to bind to reserved ports.

authconfig

policy for authconfig

automount

Filesystem automounter service.

avahi

mDNS/DNS-SD daemon implementing Apple ZeroConf architecture.

awstats

Log file analyzer for advanced statistics.

backup

System backup scripts.

bacula

Cross platform network backup.

bcfg2

configuration management suite.

bind

Berkeley Internet name domain DNS server.

bird

BIRD Internet Routing Daemon.

bitlbee

Tunnels instant messaging traffic to a virtual IRC channel.

blkmapd

The blkmapd daemon performs device discovery and mapping for pNFS block layout client.

blueman

Tool to manage Bluetooth devices.

bluetooth

Bluetooth tools and system services.

boinc

policy for boinc

brctl

Utilities for configuring the Linux ethernet bridge.

brltty

brltty is refreshable braille display driver for Linux/Unix

bugzilla

Bugtracker.

bumblebee

policy for bumblebee

cachefilesd

policy for cachefilesd

calamaris

Squid log analysis.

callweaver

PBX software.

canna

Kana-kanji conversion server.

ccs

Cluster Configuration System.

cdrecord

Record audio or data Compact Discs from a master.

certmaster

Remote certificate distribution framework.

certmonger

Certificate status monitor and PKI enrollment client.

certwatch

Digital Certificate Tracking.

cfengine

System administration tool for networks.

cgdcbxd

policy for cgdcbxd

cgroup

libcg is a library that abstracts the control group file system in Linux.

chrome

policy for chrome

chronyd

Chrony NTP background daemon.

cinder

openstack-cinder

cipe

Encrypted tunnel daemon.

clamav

ClamAV Virus Scanner

clockspeed

Clock speed measurement and manipulation.

clogd

Clustered Mirror Log Server.

cloudform

cloudform policy

cmirrord

Cluster mirror log daemon.

cobbler

Cobbler installation server.

cockpit

policy for cockpit

collectd

Statistics collection daemon for filling RRD files.

colord

GNOME color manager

comsat

Comsat, a biff server.

condor

policy for condor

conman

Conman is a program for connecting to remote consoles being managed by conmand

consolekit

Framework for facilitating multiple user sessions on desktops.

container

The open-source application container engine.

corosync

Corosync Cluster Engine.

couchdb

Document database server.

courier

Courier IMAP and POP3 email servers

cpucontrol

Services for loading CPU microcode and CPU frequency scaling.

cpufreqselector

Command-line CPU frequency settings.

cpuplug

cpuplugd - Linux on System z CPU and memory hotplug daemon

cron

Periodic execution of scheduled commands.

ctdb

policy for ctdbd

cups

Common UNIX printing system.

cvs

Concurrent versions system.

cyphesis

Cyphesis WorldForge game server.

cyrus

Cyrus is an IMAP service intended to be run on sealed servers.

daemontools

Collection of tools for managing UNIX services.

dante

Dante msproxy and socks4/5 proxy server.

dbadm

Database administrator role.

dbskk

Dictionary server for the SKK Japanese input method system.

dbus

Desktop messaging bus

dcc

Distributed checksum clearinghouse spam filtering.

ddclient

Update dynamic IP address at DynDNS.org.

ddcprobe

ddcprobe retrieves monitor and graphics card information.

denyhosts

SSH dictionary attack mitigation.

devicekit

Devicekit modular hardware abstraction layer

dhcp

Dynamic host configuration protocol server.

dictd

Dictionary daemon.

dirmngr

Server for managing and downloading certificate revocation lists.

dirsrv

policy for dirsrv

dirsrv-admin

Administration Server for Directory Server, dirsrv-admin.

distcc

Distributed compiler daemon.

djbdns

Small and secure DNS daemon.

dkim

DomainKeys Identified Mail milter.

dmidecode

Decode DMI data for x86/ia64 bioses.

dnsmasq

DNS forwarder and DHCP server.

dnssec

policy for dnssec_trigger

dnssectrigger

Enables DNSSEC protection for DNS traffic.

dovecot

Dovecot POP and IMAP mail server

dpkg

Debian package manager.

drbd

Mirrors a block device over the network to another machine.

dspam

policy for dspam

entropyd

Generate entropy from audio input.

etcd

A highly-available key value store for shared configuration.

evolution

Evolution email client.

exim

Mail transfer agent.

fail2ban

Update firewall filtering to ban IP addresses with too many password failures.

fcoe

Fibre Channel over Ethernet utilities.

fetchmail

Remote-mail retrieval and forwarding utility.

finger

Finger user information service.

firewalld

Service daemon with a D-BUS interface that provides a dynamic managed firewall.

firewallgui

system-config-firewall dbus system service.

firstboot

Final system configuration run during the first boot after installation of Red Hat/Fedora systems.

fprintd

DBus fingerprint reader service.

freeipmi

Remote-Console (out-of-band) and System Management Software (in-band) based on Intelligent Platform Management Interface specification

freqset

policy for freqset

ftp

File transfer protocol service.

fwupd

fwupd is a daemon to allow session software to update device firmware

games

Various games.

gatekeeper

OpenH.323 Voice-Over-IP Gatekeeper.

gdomap

GNUstep distributed object mapper.

gear

The open-source application container engine.

geoclue

Geoclue is a D-Bus service that provides location information

gift

Peer to peer file sharing tool.

git

GIT revision control system.

gitosis

Tools for managing and hosting git repositories.

glance

OpenStack image registry and delivery service.

glusterd

policy for glusterd

gnome

GNU network object model environment (GNOME)

gnomeclock

Gnome clock handler for setting the time.

gpg

Policy for GNU Privacy Guard and related programs.

gpm

General Purpose Mouse driver.

gpsd

gpsd monitor daemon.

gssproxy

policy for gssproxy

guest

Least privledge terminal user role.

hadoop

Software for reliable, scalable, distributed computing.

hal

Hardware abstraction layer.

hddtemp

Hard disk temperature tool running as a daemon.

hostapd

policy for hostapd

howl

Port of Apple Rendezvous multicast DNS.

hsqldb

Hsqldb is transactional database engine with in-memory and disk-based tables, supporting embedded and server modes.

hwloc

Dump topology and locality information from hardware tables.

hypervkvp

policy for hypervkvp

i18n_input

IIIMF htt server.

icecast

ShoutCast compatible streaming media server.

ifplugd

Bring up/down ethernet interfaces based on cable detection.

imaze

iMaze game server.

inetd

Internet services daemon.

inn

Internet News NNTP server.

iodine

IP over DNS tunneling daemon.

iotop

Simple top-like I/O monitor

ipa

Policy for IPA services.

ipmievd

IPMI event daemon for sending events to syslog.

irc

IRC client policy.

ircd

IRC servers.

irqbalance

IRQ balancing daemon.

iscsi

Establish connections to iSCSI devices.

isns

Internet Storage Name Service.

jabber

Jabber instant messaging server

java

Java virtual machine

jetty

Jetty - HTTP server and Servlet container

jockey

policy for jockey

journalctl

policy for journalctl

kde

Policy for KDE components

kdump

Kernel crash dumping mechanism

kdumpgui

system-config-kdump GUI

keepalived

keepalived - load-balancing and high-availability service

kerberos

MIT Kerberos admin and KDC

kerneloops

Service for reporting kernel oopses to kerneloops.org.

keyboardd

policy for system-setup-keyboard daemon

keystone

policy for keystone

kismet

IEEE 802.11 wireless LAN sniffer.

kmscon

Terminal emulator for Linux graphical console

ksmtuned

Kernel Samepage Merging Tuning Daemon.

ktalk

talk-server - daemon programs for the Internet talk

kubernetes

SELinux policy for Kubernetes container management

kudzu

Hardware detection and configuration tools.

l2tp

Layer 2 Tunneling Protocol daemons.

ldap

OpenLDAP directory server

lightsquid

Log analyzer for squid proxy.

likewise

Likewise Active Directory support for UNIX.

linuxptp

implementation of the Precision Time Protocol (PTP) according to IEEE standard 1588 for Linux.

lircd

Linux infared remote control daemon.

livecd

Tool for building alternate livecd for different os and policy versions.

lldpad

Intel LLDP Agent.

loadkeys

Load keyboard mappings.

lockdev

Library for locking devices.

logrotate

Rotate and archive system logs

logwatch

System log analyzer and reporter.

lpd

Line printer daemon

lsm

libStorageMgmt plug-in daemon

lttng-tools

LTTng 2.x central tracing registry session daemon.

mailman

Mailman is for managing electronic mail discussion and e-newsletter lists

mailscanner

E-mail security and anti-spam package for e-mail gateway systems.

man2html

A Unix manpage-to-HTML converter.

mandb

policy for mandb

mcelog

Linux hardware error daemon.

mcollective

policy for mcollective

mediawiki

Mediawiki policy

memcached

high-performance memory object caching system

milter

Milter mail filters

minidlna

MiniDLNA lightweight DLNA/UPnP media server

minissdpd

Daemon used by MiniUPnPc to speed up device discoveries.

mip6d

Mobile IPv6 and NEMO Basic Support implementation

mirrormanager

policy for mirrormanager

mock

policy for mock

modemmanager

Provides a DBus interface to communicate with mobile broadband (GSM, CDMA, UMTS, ...) cards.

mojomojo

MojoMojo Wiki.

mon_statd

policy for mon_statd

mongodb

Scalable, high-performance, open source NoSQL database.

mono

Run .NET server and client applications on Linux.

monop

Monopoly daemon.

motion

Detect motion using a video4linux device

mozilla

Policy for Mozilla and related web browsers

mpd

Music Player Daemon.

mplayer

Mplayer media player and encoder.

mrtg

Network traffic graphing.

mta

Policy common to all email tranfer agents.

munin

Munin network-wide load graphing (formerly LRRD)

mysql

Policy for MySQL

mythtv

policy for mythtv_script

naemon

New monitoring suite that aims to be faster and more stable, while giving you a clearer view of the state of your network.

nagios

Net Saint / NAGIOS - network monitoring server

namespace

policy for namespace

ncftool

Cross-platform network configuration library.

nessus

Network scanning daemon.

networkmanager

Manager for dynamically switching between networks.

ninfod

Respond to IPv6 Node Information Queries

nis

Policy for NIS (YP) servers and clients

nova

openstack-nova

nscd

Name service cache daemon

nsd

Authoritative only name server

nslcd

nslcd - local LDAP name service daemon.

nsplugin

policy for nsplugin

ntop

A network traffic probe similar to the UNIX top command.

ntp

Network time protocol daemon

numad

policy for numad

nut

nut - Network UPS Tools

nx

NX remote desktop.

oav

Open AntiVirus scannerdaemon and signature update.

obex

D-Bus service providing high-level OBEX client and server side functionality.

oddjob

Oddjob provides a mechanism by which unprivileged applications can request that specified privileged operations be performed on their behalf.

oident

An ident daemon with IP masq/NAT support and the ability to specify responses.

openca

Open Certificate Authority.

openct

Service for handling smart card readers.

opendnssec

policy for opendnssec

openfortivpn

Fortinet compatible SSL VPN daemons.

openhpi

Open source implementation of the Service Availability Forum Hardware Platform Interface.

openhpid

policy for openhpid

openshift

policy for openshift

openshift-origin
opensm

Opensm is an InfiniBand compliant Subnet Manager and Administration, and runs on top of OpenIB

openvpn

full-featured SSL VPN solution.

openvswitch

policy for openvswitch

openwsman

WS-Management Server

oracleasm

policy for oracleasm

osad

Client-side service written in Python that responds to pings and runs rhn_check when told to by osa-dispatcher.

pacemaker

>A scalable high-availability cluster resource manager.

pads

Passive Asset Detection System.

passenger

Ruby on rails deployment for Apache and Nginx servers.

pcmcia

PCMCIA card management services.

pcp

The pcp command summarizes the status of a Performance Co-Pilot (PCP) installation

pcscd

PCSC smart card service.

pdns

PowerDNS DNS server.

pegasus

The Open Group Pegasus CIM/WBEM Server.

perdition

Perdition POP and IMAP proxy.

pesign

pesign utility for signing UEFI binaries as well as other associated tools

pingd

Pingd of the Whatsup cluster node up/down detection utility.

piranha

policy for piranha

pkcs

Implementations of the Cryptoki specification.

pkcs11proxyd

pkcs11proxyd-softhsm-ctl - manage the isolated PKCS #11 daemon with softhsm

pki

policy for pki

plymouthd

Plymouth graphical boot

podsleuth

Podsleuth is a tool to get information about an Apple (TM) iPod (TM).

policykit

Policy framework for controlling privileges for system-wide services.

polipo

Caching web proxy.

portage

Package Management System.

portmap

RPC port mapping service.

portreserve

Reserve well-known ports in the RPC port range.

portslave

Portslave terminal server software.

postfix

Postfix email server

postfixpolicyd

Postfix policy server.

postgrey

Postfix grey-listing server.

ppp

Point to Point Protocol daemon creates links in ppp networks

prelink

Prelink ELF shared library mappings.

prelude

Prelude hybrid intrusion detection system

privoxy

Privacy enhancing web proxy.

procmail

Procmail mail delivery agent

prosody

policy for prosody

psad

Intrusion Detection and Log Analysis with iptables.

ptchown

helper function for grantpt(3), changes ownship and permissions of pseudotty.

publicfile

publicfile supplies files to the public through HTTP and FTP.

pulseaudio

Pulseaudio network sound server.

puppet

Puppet client daemon

pwauth

policy for pwauth

pxe

Server for the PXE network boot protocol.

pyzor

Pyzor is a distributed, collaborative spam detection and filtering network.

qemu

QEMU machine emulator and virtualizer

qmail

Qmail Mail Server

qpid

policy for qpidd

quantum

Virtual network service for Openstack.

quota

File system quota management

rabbitmq

AMQP server written in Erlang.

radius

RADIUS authentication and accounting server.

radvd

IPv6 router advertisement daemon.

raid

RAID array management tools

rasdaemon

The rasdaemon program is a daemon with monitors the RAS trace events from /sys/kernel/debug/tracing

razor

A distributed, collaborative, spam detection and filtering network.

rdisc

Network router discovery daemon.

readahead

Read files into page cache for improved performance.

realmd

dbus system service which manages discovery and enrollment in realms and domains like Active Directory or IPA

redis

Advanced key-value store

remotelogin

Policy for rshd, rlogind, and telnetd.

resmgr

Resource management daemon.

rgmanager

rgmanager - Resource Group Manager

rhcs

RHCS - Red Hat Cluster Suite

rhev

rhev polic module contains policies for rhev apps

rhgb

Red Hat Graphical Boot

rhnsd

policy for rhnsd

rhsmcertd

Subscription Management Certificate Daemon policy

ricci

Ricci cluster management agent

rkhunter

policy for rkhunter

rkt

CLI for running app containers

rlogin

Remote login daemon.

rngd

Check and feed random data from hardware device to kernel random device.

rolekit

Daemon for Linux systems providing a stable D-BUS interface to manage the deployment of Server Roles.

roundup

Roundup Issue Tracking System.

rpc

Remote Procedure Call Daemon for managment of network based process communication

rpcbind

Universal Addresses to RPC Program Number Mapper

rpm

Policy for the RPM package manager.

rshd

Remote shell service.

rssh

Restricted (scp/sftp) only shell.

rsync

Fast incremental file transfer for synchronization

rtas

Platform diagnostics report firmware events.

rtkit

Realtime scheduling for user processes.

rwho

Who is logged in on other machines?

samba

SMB and CIFS client/server programs for UNIX and name Service Switch daemon for resolving names from Windows NT servers.

sambagui

system-config-samba dbus service.

samhain

Check file integrity.

sandbox

policy for sandbox

sandboxX

policy for sandboxX

sanlock

Sanlock - lock manager built on shared storage.

sasl

SASL authentication server

sbd

policy for sbd

sblim

Standards Based Linux Instrumentation for Manageability.

screen

GNU terminal multiplexer

sectoolm

Sectool security audit tool

sendmail

Policy for sendmail.

sensord

Sensor information logging daemon

setroubleshoot

SELinux troubleshooting service

sge

Policy for gridengine MPI jobs

shorewall

Shoreline Firewall high-level tool for configuring netfilter

shutdown

System shutdown command

slocate

Update database for mlocate.

slpd

OpenSLP server daemon to dynamically register services.

slrnpull

Service for downloading news feeds the slrn newsreader.

smartmon

Smart disk monitoring daemon.

smokeping

Smokeping network latency measurement.

smoltclient

The Fedora hardware profiler client.

smsd

The SMS Server Tools are made to send and receive short messages through GSM modems. It supports easy file interfaces and it can run external programs for automatic actions.

smstools

Tools to send and receive short messages through GSM modems or mobile phones.

snapper

policy for snapperd

snmp

Simple network management protocol services.

snort

Snort network intrusion detection system.

sosreport

Generate debugging information for system.

soundserver

sound server for network audio server programs, nasd, yiff, etc

spamassassin

Filter used for removing unsolicited email.

speech-dispatcher

speech-dispatcher - server process managing speech requests in Speech Dispatcher

speedtouch

Alcatel speedtouch USB ADSL modem

squid

Squid caching http proxy server.

sslh

policy for sslh

sssd

System Security Services Daemon

stapserver

Instrumentation System Server

stunnel

SSL Tunneling Proxy.

svnserve

policy for svnserve

swift

policy for swift

swift_alias

swift_alias policy module

sxid

SUID/SGID program monitoring.

sysstat

Reports on various system states.

targetd

Targetd is a service to allow the remote configuration of block device volumes and file systems within dedicated pools

tcpd

TCP daemon.

tcsd

TSS Core Services daemon.

telepathy

Telepathy communications framework.

telnet

Telnet daemon.

tftp

Trivial file transfer protocol daemon

tgtd

Linux Target Framework Daemon.

thin

thin policy

thumb

policy for thumb

thunderbird

Thunderbird email client.

timidity

MIDI to WAV converter and player configured as a service.

tmpreaper

Manage temporary directory sizes and file ages.

tomcat

policy for tomcat

tor

The onion router.

transproxy

Portable Transparent Proxy Solution.

tripwire

File integrity checker.

tuned

Dynamic adaptive system tuning daemon.

tvtime

High quality television application.

tzdata

Time zone updater.

ucspitcp

UNIX Client-Server Program Interface for TCP.

udisks2

udisks - Disk Manager

ulogd

Iptables/netfilter userspace logging daemon.

uml

User mode linux tools and services.

updfstab

Red Hat utility to change fstab.

uptime

Daemon to record and keep track of system up times.

usbmodules

List kernel modules of USB devices.

usbmuxd

USB multiplexing daemon for communicating with Apple iPod Touch and iPhone.

userhelper

SELinux utility to run a shell with a new role

usernetctl

User network interface configuration helper.

uucp

Unix to Unix Copy.

uuidd

UUID generation daemon.

uwimap

University of Washington IMAP toolkit POP3 and IMAP mail server.

varnishd

Varnishd http accelerator daemon.

vbetool

run real-mode video BIOS code to alter hardware state.

vdagent

Spice agent for Linux.

vhostmd

Virtual host metrics daemon.

virt

Libvirt virtualization API

vlock

Lock one or more sessions on the Linux console.

vmtools

VMware Tools daemon

vmware

VMWare Workstation virtual machines.

vnstatd

Console network traffic monitor.

vpn

Virtual Private Networking client

w3c

W3C Markup Validator.

watchdog

Software watchdog.

wdmd

watchdog multiplexing daemon

webadm

Web administrator role.

webalizer

Web server log analysis.

wine

Wine Is Not an Emulator. Run Windows programs in Linux.

wireshark

Wireshark packet capture tool.

wm

X Window Managers

xen

Xen hypervisor

xfs

X Windows Font Server.

xguest

Least privledge xwindows user role.

xprint

A X11-based print system and API.

xscreensaver

Modular screen saver and locker for X11.

yam

Yum/Apt Mirroring.

zabbix

Distributed infrastructure monitoring

zarafa

Zarafa collaboration platform.

zebra

Zebra border gateway protocol network routing service

zoneminder

policy for zoneminder

zosremote

z/OS Remote-services Audit dispatcher plugin.